Splunk Enterprise Security (ES) Consultant...

System One
Arlington, WI, United States
30 days ago
Apply on www.juju.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Bash Shell Software Debugging Linux Perl (Programming Language) Information Model Python (Programming Language) Regular Expressions Security Information and Event Management Data Streaming Scripting Data Ingestion Information Technology
+1 more
Splunk

Job description

  • Develop custom detection content: correlation searches, notable events, alerts, reports, and visualizations to surface threat activity

  • Build and maintain Splunk Apps and Technology Add-ons (TAs)

  • Onboard new data sources and normalize them to the Common Information Model (CIM)

  • Optimize data flow and ingestion using aggregation, filtering, and pipeline tuning

  • Configure notable event actions, action menus, and Adaptive Responses

  • Tune detections to cut noise and surface what matters, including risk-based alerting where applicable

  • Build dashboards that highlight anomalies, trends, and security and operational metrics

  • Support and optimize large distributed clustered Splunk environments (search heads, indexers, forwarders, deployment servers)

  • Partner with the client’s security and SOC teams, debug complex integration and configuration issues

  • Document processes, procedures, and key engineering decisions, System One, and its subsidiaries including Joulé, ALTA IT Services, CM Access, TPGS, and MOUNTAIN, LTD., are leaders in delivering workforce solutions and integrated services across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible full-time employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.

Requirements

  • Several years of hands-on Splunk experience, with real ES implementation, content development, and tuning

  • Strong SPL and regular expressions

  • Scripting in Python, Perl, or Bash

  • Solid grasp of CIM and data onboarding and normalization at scale

  • Experience supporting clustered Splunk environments in SOC or NOC settings

  • SIEM data modeling experience on a platform at scale

  • Proficiency in Linux, including editing and maintaining Splunk config files and apps

  • Comfortable working consultatively with client teams and explaining the why behind the work

  • Splunk certifications (Core Certified Consultant, ES Certified Admin, Architect) are a plus but not required

  • Demonstrated ES delivery experience carries more weight than paper

About the company

System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:24 min

Evaluating formal AWS certifications versus raw practical engineering experience

Jan Giacomelli · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all